VYPR

CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-15 · CAPEC-43 · CAPEC-6 · CAPEC-88

CVEs mapped to this weakness (6,524)

page 224 of 327
  • CVE-2024-42060HigSep 3, 2024
    risk 0.47cvss 7.2epss 0.01

    A post-authentication command injection vulnerability in Zyxel ATP series firmware versions from V4.32 through V5.38, USG FLEX series firmware versions from V4.50 through V5.38, USG FLEX 50(W) series firmware versions from V4.16 through V5.38, and USG20(W)-VPN series firmware…

  • CVE-2024-42059HigSep 3, 2024
    risk 0.47cvss 7.2epss 0.01

    A post-authentication command injection vulnerability in Zyxel ATP series firmware versions from V5.00 through V5.38, USG FLEX series firmware versions from V5.00 through V5.38, USG FLEX 50(W) series firmware versions from V5.00 through V5.38, and USG20(W)-VPN series firmware…

  • CVE-2024-7728HigAug 14, 2024
    risk 0.47cvss 7.2epss 0.01

    The specific CGI of the CAYIN Technology CMS does not properly validate user input, allowing a remote attacker with administrator privileges to inject OS commands into the specific parameter and execute them on the remote server.

  • CVE-2024-42370HigAug 12, 2024
    risk 0.47cvss 8.3epss 0.01

    Litestar is an Asynchronous Server Gateway Interface (ASGI) framework. In versions 2.10.0 and prior, Litestar's `docs-preview.yml` workflow is vulnerable to Environment Variable injection which may lead to secret exfiltration and repository manipulation. This issue grants a…

  • CVE-2024-21880HigAug 12, 2024
    risk 0.47cvss 7.2epss 0.02

    Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability via the url parameter of an authenticated enpoint in Enphase IQ Gateway (formerly known as Enphase) allows OS Command Injection.This issue affects Envoy: 4.x <= 7.x

  • CVE-2024-3659HigAug 8, 2024
    risk 0.47cvss 7.2epss 0.02

    Firmware in KAON AR2140 routers, prior to versions 3.2.50 and 4.2.16, is vulnerable to a shell command injection via sending a crafted request to one of the endpoints. In order to exploit this vulnerability, one has to have access to the administrative portal of the router.

  • CVE-2024-38512HigJul 26, 2024
    risk 0.47cvss 7.2epss 0.01

    A privilege escalation vulnerability was discovered in XCC that could allow an authenticated XCC user with elevated privileges to perform command injection via specially crafted IPMI commands.

  • CVE-2024-38511HigJul 26, 2024
    risk 0.47cvss 7.2epss 0.01

    A privilege escalation vulnerability was discovered in an upload processing functionality of XCC that could allow an authenticated XCC user with elevated privileges to perform command injection via specially crafted file uploads.

  • CVE-2024-38510HigJul 26, 2024
    risk 0.47cvss 7.2epss 0.01

    A privilege escalation vulnerability was discovered in the SSH captive command shell interface that could allow an authenticated XCC user with elevated privileges to perform command injection via specially crafted file uploads.

  • CVE-2024-38508HigJul 26, 2024
    risk 0.47cvss 7.2epss 0.01

    A privilege escalation vulnerability was discovered in the web interface or SSH captive command shell interface of XCC that could allow an authenticated XCC user with elevated privileges to perform command injection via a specially crafted request.

  • CVE-2024-39345HigJul 24, 2024
    risk 0.47cvss 7.2epss 0.01

    AdTran 834-5 HDC17600021F1 (SmartOS 11.1.1.1) devices enable the SSH service by default and have a hidden, undocumented, hard-coded support account whose password is based on the devices MAC address. All of the devices internet interfaces share a similar MAC address that only…

  • CVE-2024-28750HigJul 9, 2024
    risk 0.47cvss 7.2epss 0.01

    A remote attacker with high privileges may use a deleting file function to inject OS commands.

  • CVE-2024-28749HigJul 9, 2024
    risk 0.47cvss 7.2epss 0.01

    A remote attacker with high privileges may use a writing file function to inject OS commands.

  • CVE-2024-28748HigJul 9, 2024
    risk 0.47cvss 7.2epss 0.01

    A remote attacker with high privileges may use a reading file function to inject OS commands.

  • CVE-2023-50383HigJul 8, 2024
    risk 0.47cvss 7.2epss 0.02

    Three os command injection vulnerabilities exist in the boa formWsc functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted series of HTTP requests can lead to arbitrary command execution. An attacker can send a series of HTTP requests to trigger these…

  • CVE-2023-50382HigJul 8, 2024
    risk 0.47cvss 7.2epss 0.02

    Three os command injection vulnerabilities exist in the boa formWsc functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted series of HTTP requests can lead to arbitrary command execution. An attacker can send a series of HTTP requests to trigger these…

  • CVE-2023-50381HigJul 8, 2024
    risk 0.47cvss 7.2epss 0.03

    Three os command injection vulnerabilities exist in the boa formWsc functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted series of HTTP requests can lead to arbitrary command execution. An attacker can send a series of HTTP requests to trigger these…

  • CVE-2024-5672HigJul 3, 2024
    risk 0.47cvss 7.2epss 0.01

    A high privileged remote attacker can execute arbitrary system commands via GET requests due to improper neutralization of special elements used in an OS command.

  • CVE-2024-39351HigJun 28, 2024
    risk 0.47cvss 7.2epss 0.02

    A vulnerability regarding improper neutralization of special elements used in an OS command ('OS Command Injection') is found in the NTP configuration. This allows remote authenticated users with administrator privileges to execute arbitrary commands via unspecified vectors. The…

  • CVE-2023-47802HigJun 28, 2024
    risk 0.47cvss 7.2epss 0.01

    A vulnerability regarding improper neutralization of special elements used in an OS command ('OS Command Injection') is found in the IP block functionality. This allows remote authenticated users with administrator privileges to execute arbitrary commands via unspecified…